Bet it might be because of a combination of compliance and cost. Storing logs at that scale is not cheap
funny thing - if you have these things in default and someone deletes a user, you won't know who did such action after 30 days (meaning you not only can not recover the user, but also will not know who performed the action)
edit -as for the compliance, personally not aware of it, but you should be able to at least have a retention policy option for it and since most companies will just put it into a storage account or log analytics I don't think it's a matter of that